HomeSecurityRussia: Meduza Stealer administrators arrested

Russia: Meduza Stealer Administrators Arrested

Russian authorities have announced the arrest of three people in Moscow, accused of being behind the creation and distribution of Meduza Stealer, one of the most sophisticated data-stealing programs released on the dark web in recent years.

Jellyfish Stealer

The news was confirmed by Irina Volk , a Russian police general and spokeswoman for the Interior Ministry, in a post on Telegram . The official noted that the operation was carried out by the Department for Combating Cybercrime (UBK) in cooperation with the Astrakhan region police .

“Meduza Stealer”: A cyber theft tool

According to the preliminary investigation, the arrested individuals had developed and started distributing the Meduza Stealer malware about two years ago, via specialized hacker forums. Meduza operated as a “malware-as-a-service” (MaaS), a subscription service model that allowed other cybercriminals to rent it for their own use, in exchange for a fee or percentage of the profits from the attacks.

See also: Ukrainian accused of participating in Conti ransomware attacks

The software was capable of credentials account, passwords, cryptocurrency wallet data, and information stored in victims' browsers. In fact, a particularly dangerous feature allowed it to "revive" expired Chrome cookies, making it easier to take over accounts even when users were logged out.

From “Meduza” to “Aurora”: The same brains behind different malware

Well-known cybersecurity researcher g0njxa, who monitors the evolution of info-stealers on the dark web, reported that the same group was also behind “Aurora Stealer”, another malware-as-a-service that had appeared in 2022. Both programs were considered particularly profitable, as they offered their users ready-made tools for cyber theft, without requiring specialized technical knowledge.

The arrest of this group could be a significant blow to the underground ecosystem of MaaS platforms, which has experienced a huge boom in recent years, turning cybercrime into a “subscription industry”.

Russia: Meduza Stealer Administrators Arrested

Russian “tolerance” and the overthrow of the rule

Russia has traditionally been criticized for its passive stance toward hackers operating within its borders, with the unwritten rule that they do not attack Russian targets. However, in the case of Meduza, it appears that the software's creators broke this "rule.

See also: Kimsuky and Lazarus teams use new tools

As Volk reported, one of the victims of the group's attacks was an institution in the Astrakhan region, from which confidential data was stolen in May 2025. This attack prompted authorities to launch a criminal investigation under Article 273, Part 2 of the Russian Criminal Code, which deals with “creation, use and distribution of malicious programs.

Botnets and parallel businesses

During the investigation, Russian authorities discovered that the arrested individuals were not limited to Meduza Stealer. They had also developed botnet malware, a system that connects infected computers into a single network, allowing remote execution of commands and bypassing the security mechanisms of the target systems.

The existence of this botnet indicates that the group operated at a professional level, with clearly defined roles and goals, more reminiscent of a corporate structure than individual hackers.

Russia: Meduza Stealer Administrators Arrested

A message with multiple recipients

Irina Volk concluded her statement by saying that police are working to identify all accomplices and that further arrests are possible . While this is a rare move by Russia to crack down on cybercrime, analysts believe the case could have political implications – either as a message of “legitimacy” to the West or as an attempt to control the domestic digital underworld .

See also: Researchers create Linux Rootkit that evades detection

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In any case, the Meduza case reminds us that cybercrime has now escaped the underground and anonymous screens: it operates with corporate logic, global reach and consequences that affect governments, organizations and ordinary citizens.

The “fall” of the creators of Meduza Stealer may just be the beginning of a new era for digital crime — and for those who pursue it.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS